Thursday, March 6, 2014

Sound as virus!!! Can a computer virus communicate Via ultrasound signals?

One of the go-to strategies for securing a computer network when a machine is infected with malware is to remove that machine from the network. This effectively prevents the malware from spreading to other devices. This Technique is called as Air-Gapping which isolate the system by introducing air gap by removing Network Connectivity.But still, Hacker Can Infect your machine if it's not connected to Network using “Air-Gap Malware”.

How does it work and how it came into existence?

Research has shown that the sounds of a dot matrix printer can be used to reverse-engineer the content being printed. In effect, this means that any person sitting in the reception area of the doctor can record the sound of the printer and can reconstruct the printed text.
Air-gap malware is that which is able to jump the air-gap by "translating" malicious computer code into high-frequency sound, then transmitting that sound to infect nearby computers.

Computer data can't travel over the air in its raw form, but your computer's sound card is more than enough to "broadcast" the malware as the inaudible sound that interacts with other machines. It doesn't care what network a computer is on.

Scientists claims that they have created computer virus that transfers stolen data using inaudible sounds

Just using the built-in speakers and microphone in a pair of commercially available laptops, the researchers were able to transfer small amounts of sensitive data across a distance of almost 65 feet(This distance can be increased using a network of controlled devices). The Scientists build the software but the One significant drawback of the that the data transmission rate was only 20 bits per second - enough to send basic text, but too small to transfer any larger multimedia, such as video. With Such as small bandwidth, only critical information can be shared like keystrokes private encryption keys or maybe malicious commands to an infected piece of construction."

Consequences-

The attacker would probably have to be very sophisticated to be able to pull off something like this." There's not really a way to proactively protect yourself from air-gap malware. The techniques that go into employing air-gap malware are complex and can only be orchestrated by a very skilled hacker

It will be very lethal when used for Cyber Warfare a Global Digital WeaponGovernment agencies can leverage this technique since they have ample money and time to hire sophisticated attacker and involve in research for developing malware which can share data at high transmission rate.


Monday, January 20, 2014

CIOs' decision Criteria may not be solely dependent on Compliance in present Dynamics

Compliance should no longer dominate CIOs’ decision making. Instead, it should be viewed as a risk, says Gartner. The research firm suggests compliance should be incorporated into risk management, rather than security being incorporated into compliance as most companies have been doing until now.

“By simply trying to keep up with individual compliance requirements, organizations become rule followers, rather than risk leaders". Compliance should be treated as a domain of risk within a formal risk management program and should not be allowed to dominate decision-making.

Compliance is treated as a legal or regulatory requirement which is evaluated based on predefined checkbox matrix. The common myth is organization feels doing so achieve Security within their functions. An organization needs to wider the boundaries and treat compliance as a risk in an overall strategy to effectively place security it's due importance.

In coming future, there will be transition drift from compliance-based to risk-based security.Compliance will be placed at a right position in CIO agenda but it won't be the only decision making a factor.

Thursday, September 26, 2013

Monday, September 23, 2013

People are Not Robots-It’s a Business

People, Process & Technology are 3 critical gears of any system. The organization is spending humongous effort in developing a consistent environment for building services, solutions, products for a community. Conceiving the services may be worrisome due to over reminded buzz world called “Cyber Security”. Cyber Security is often associated with the External hacker community and very less preference given to Internal Employee. Reason has been a trust; However, Responsibility always comes with Power which has profound root under the ground. 

People are Not a Robot, they will try to take control of systems or react differently if the security culture is not deep penetrated inside the foundation.”

News broke this week about IBM’s latest file leak, where a former employee with access to confidential information regarding IBM’s play in cloud computing technology leaked hundreds of pages of documentation, shedding light on IBM’s weakness within the cloud computing industry. The breaches similar to this has affected the stock emotion and further reputation of the company in delivery services.  

Inside threat is the area of silence and always given second preference; however, the results are more painful than External threats. 
A survey was conducted on Insider Data Privacy, which has revealed some alarming situations



The Typical data movement practice followed are removing data was to copy it to a staging site on the Internet, such as iDisk or DropBox, with 43% choosing this channel; 36% used webmail to send out files as attachments, 29% copied information onto a USB device and 3% feels taking printout.

Data Leak Prevention system should be enforced at the foundation of the system not leaving any member out of its perimeter. This ensures data(structured/unstructured) protection to minimize the risk of a breach or a loss of intellectual property. A strong segregation of duties measures is incorporated to mitigate risk arising from Administration perspective.A careful attention should be given, so that productive working relationship of the Employee and Organization should not get restricted.

Tuesday, September 10, 2013

Cyber Crime History (1820) to Today's enforcement law’s (2013)

Cyber crime has shown a serious threat to society since many decades. We will not believe the first cyber crime recorded in late 1820.Yes, it's a shocking fact!!!
Abacus, which is thought to be the earliest form of a computer, has been around since 3500 B.C. in India, Japan, and China. Joseph-Marie Jacquard, a textile manufacturer in France, produced the loom. This device allowed the repetition of a series of steps in the weaving of special fabrics. This resulted in a fear amongst Jacquard's employees that their traditional employment and livelihood were being threatened. They committed acts of sabotage to discourage Jacquard from further use of the new technology.

Now, Technology has transverse  to many folds from standalone computers to messed network(like personal area network (PAN),local area network (LAN),home area network (HAN), storage area network (SAN),campus area network (CAN),Backbone network, Metropolitan area network (MAN), wide area network (WAN), virtual private network (VPN)) and etc. with different Technology modes.

To manage and maintain confidentiality, Integrity, and Availability of such complex system, a CyberLAW has to be enforced to minimize the challenges in the legal world. The disputes arise for any challenges, whether Statutory or otherwise, are terms as "CyberLAW".European Union, USA, United Nations Commission On International Trade Law (UNCITRAL) have already framed important laws to regulate cyberspace. In India, Information Technology Act (ITA) is also based on the UNCITRAL model, all cyber laws are contained in Information Technology Act, 2000.

The below list provide high-level analysis pertaining on Cyber Crime as associated IT LAW.

Cyber Crime
Brief Description(Example)
Relevant Section in IT Act
Punishments
Cyber Stalking
Stealthily or harass  a person or a group,  false accusations
 identity theft(tracking his chat)
43,65,66
3 years, or with fine up to 2 lakh
Cyber Pornography including Child Pornography
Publishing Obscene in Electronic Form involving children
67,67(2)
10 years and with fine may extend to 10 lakh
Intellectual Property Crimes
Source Code Tampering, Piracy, Copyright infringement etc.
65
3 years, or with fine up to 2 lakh
Cyber Terrorism
Protection against Cyber Terrorism
69
Imprisonment for a term, may extend to 7 years
Cyber Hacking
Destruction, Deletion, Alteration etc.
66
3 years, or with fine up to 2 lakh
Phishing
Banking Financial Frauds
43,65,66
3 years, or with fine up to 2 lakh

Friday, September 6, 2013

India in top 10 league for Spear Phishing

We discussed the aim of phishing and the modus-operandi of achieving it. Likewise, Spear Phishing is an attempt directed at specific individuals or companies to steal sensitive information rather than targeting to mass community. The probability of success, in this case, is much higher.India is upcoming country, with strong expansion in various verticals and specialized in providing IT Consulting services across the Global. One year back, India was not in a league of this competition; however, now it holds 3% share for hosting a phishing site. This is very less number but it looks to be an alarming situation down the line.  Today, the country has clearly established a footprint on the international cyber map for being in the list of top 10 hosts of phishing sites globally.
The most targeted Indian sites were classified in various categories - information technology (14.40%), education (11.90%), product sales and services (9.80%), industrial and manufacturing (7.30%), and tourism, travel, and transport (5.80%). 

The attack leaves a devastated footprint when targeted to specific customer-centric vertical.  Privacy protection is a crucial element of today’s  growing e-service demand.One of the most glaring attacks was the recent purchase of more than 15,000 online tickets on Kingfisher Airlines by fraudsters who somehow got hold of the credit card information of several cardholders, many of them foreign nationals. While it is not clear where the fraud originated, some estimates peg the loss to the carrier at Rs 17 crore.

In fact, Major Bank has been targeted and now in a race of taking corrective actions like user awareness and establishing a monitoring mechanism to track and block the site at Service Provider end. This does not look to be simply since it can be a target from the globe with different "Law of the Land" rules.

Countermeasures to avoid phishing attacks:
  • Do not click on suspicious links in email messages. In the case of any doubt, perform the simple step as mentioned in my previous blog (like identifying the email address in the message header and IP address) to identify if it’s a phishing mail.
  • Do Not reveal sensitive information over the call.
  • Do not enter personal information in a pop-up page or screen
  • Ensure the website is encrypted with an SSL certificate by looking for the padlock, ‘https’, or the green address bar when entering personal or financial information
  • Update your security software frequently, which protects you from online phishing
  • And lastly, Inform respective organization about the same to prevent further broadcasting.

Wednesday, September 4, 2013

Phishing a "Race"- How many Crosses the Battle ?




Government Phishing (“Fishing a user” ) High Volume threat

Phishing is a term, often used to describe a fraud which involves capturing personal information of users to perform unauthorized transactions or operations. Phishing can also be associated with the term fishy and I think that is how it has been originated.

In a real sense, it is achieved over call, email or hosting a website which is a replica copy of the genuine site. Attacker send a  mail which looks very similar to actual mail of the sender with a link embedded which redirect the user to site for  stealing user information

The phishing attack is not limited to Banking sector; however, it has been penetrated to other verticals like Government and Retails. A study shows around 10,000 users face phishing attacks daily in India, 65 percentage of attacks categorized under Government sector. A typical distribution of the attacks would represent as-
  • Phishing: 51.2 %
  • Virus, Trojan, worm, logic bomb: 7.7 %
  • Policy violation: 7.4 %
  • Malicious website: 6.3 %
  • Equipment theft/loss: 6.2 %
  • Suspicious network activity: 3.3 %
  • Social Engineering: 2.4 %
  • Attempted access: 0.8 %
  • Others: 5.8 %

It’s becoming a nightmare to detect phishing at a global level; however, a user careful attention can reveal its integrity. Banks and regulatory bodies like Reserve Bank of India (RBI), Income Tax (I.T) Dept. are publicizing awareness on phishing. Phishers now send emails resembling Yahoo / Rediff mail, shopping sites or regulatory bodies, like RBI / I.T. dept., asking for confidential data. 

In the case of Government vertical, let's consider a scenario where an attacker sends an email trying to lure a user to fill required detail to get a tax refund. The Email address is masked and resembles the actual email address of Government.




The attacker creates a Fraud site which looks similar to the genuine site except it doesn't have a certificate attached to it. The user is redirected to fraud site to capture sensitive and confidential information. The unsuspecting user enters their login information.


A legitimate financial institution will never ask for details of your account via an e-mail. A corollary to this rule is that never e-mail financial information over the Internet. 

Tuesday, August 27, 2013

Be Safe, It’s an Internet Frauds

We often receive emails from known and unknown sources asking for some favor or proposal. Internet fraud is a term used frequently to describe the fraudulent activities performed using the Internet as a medium. It is very easy to hide your identity and initiate the crime seating 1000 of miles away. This is generally propagated like the virus and takes a form of banking scam. The scam can be of many schemes as listed below 



























Estimates of the total losses due to the scam vary widely since many people may be too embarrassed to admit that they were gullible enough to be scammed to report the crime. In addition to the financial cost, many victims also suffer a severe emotional and psychological cost, such as losing their ability to trust people. One man from Cambridgeshire, UK, committed suicide by lighting himself on fire with petrol after realizing that the $1.2 million “internet lottery” that he won was actually a scam.

Before it’s too late let us understand how such scams are triggered. In this blog, I am going to discuss how Business proposal scam leads to financial loss and ways to identify and mitigates the same. 

I received the below email which has a very impressive offer.Let's analyze the mail.

Email Message 

Mail from Alice Farah farah_alice@voila.fr via yahoo.com 

---------------------------------------------------------------------------------------------
Dear Friend.

Greetings to you and your family, I am the manager of bill and exchange in THE BANK, I have a business of 5.5 Million United State Dollars to be transfer to your account for investment in your country, if you are ready to assist me get back to me, I will give you full details on how the fund will be transfer to you.

Be rest assured that everything will be handled confidentially because, this is a great opportunity we cannot afford to miss, as it will make our family profit a lot.

It has been 6 years go, that most of the greedy African Politicians used our bank to launder money overseas through the help of their Political advisers.

Most of the funds which they transferred out of the shores of Africa were gold and oil money that was supposed to have been used to develop the continent.

The Political advisers always inflated the amounts before transfer to foreign accounts so I also used the opportunity to divert part of the fund worth five million five hundred united state dollars I told you about and I am aware that there is no official trace of how much was transferred as all the accounts used for such transfers of fund at that particle time were closed after transfer.

I am the account officer to most of the politicians and when I discovered that they were using me to succeed in their greedy act, I also cleaned some of their banking records from the Bank files and no one cared to ask me for the money was too much for them to control, as I am sending this message to you, I was able to divert five point five Millions Dollars ($5.5M)which is in an escrow transit account belonging to no one in the bank, and now my bank is very anxious to know the real beneficiary of the funds is for they have made a lot of profits with the fund.

It has been more than five years ago and most of the politicians are no longer in power again and they don’t use our bank to transfer funds overseas anymore since their tenure had expired.

The $5.5 Million United State Dollars has been lying in the bank as unclaimed fund and I will soon retire from the bank immediately the fund is transfer into your account over there.

Immediately the fund has been successfully transfer into your account I will come to your country for the sharing of the fund, the fund will be shared 50% for me and 40% for you, and the other 10% for the orphanages home and poor with less-privilege people.

Please know that there is no one that is going to question you about the fund if you will comply with me and follow my instruction which will help us a lot to achieve this goal for everything is well secured.

Please indicate your interest in this transaction by replying back through my private email
and if you are not interested do not waste your time to reply kindly delete my message from your box ok.

Waiting to hear from you soon.

Yours Faithfully,
Mrs. Alice Farah.
------------------------------------------------------------------------------------------------------------


The best way to analyze the mail is to read the message header, which gives all the information i.e. when this mail was originated, source address, Number of hops or the device it has passed thru and so on. The below snippet shows a message header, which needs to be read from bottom in a chronological manner.

Message Header 

Please click on the below image for better resolution.




If you look at the full header information of the email you will most likely see a different reply to and/or return-path, which is the spammers email address. In our case Reply-To: alicefarah5@voila.fr is different then Return-Path: p.godpower@yahoo.com. So that means it’s a spam mail!!!The “From” address can be spoofed with your friend email address as well.

Now, let’s identify the origin of this mail. After analyzing the above message header you can get the below matrix showing how this message has transverse from different network and system. So that’s means the message you send over the internet can be tracked easily and necessary actions can be taken 

From
To
Time received
41.203.233.236
web161306.mail.bf1.yahoo.com [Web]
8/19/2013 7:06:33 PM
127.0.0.1
omp1005.mail.bf1.yahoo.com [Yahoo NNFMP]
8/19/2013 7:06:33 PM
98.139.212.196
tm12.bullet.mail.bf1.yahoo.com [Yahoo NNFMP]
8/19/2013 7:06:33 PM
98.139.215.141
nm47.bullet.mail.bf1.yahoo.com [Yahoo NNFMP]
8/19/2013 7:06:34 PM
nm47-vm1.bullet.mail.bf1.yahoo.com.
mx.google.com
[Google]
8/19/2013 7:06:34 PM
10.224.160.130
[SMTP]
[Google]
8/19/2013 7:06:34 PM
10.52.155.4
[SMTP]
[Google]
8/19/2013 7:06:34 PM

The origin of this message is from IP Address - 41.203.233.236.If you perform Whois IP Address lookup the below detail can be obtained. 

person:         Emmanuel GUIGMA
nic-hdl:        EG4-AFRINIC
address:        ONATEL, 01 P.O. BOX 10 000
address:        Ouagadougou 01
address:        Burkina Faso
address:        OUAGADOUGOU 01 BP 10000
address:        Burkina Faso
e-mail:         guigma@onatel.bf
phone:          +22650305847
fax-no:         +22650315386
source:    AFRINIC # Filtered 

It shows the origin of this message is from Africa.

Be safe and Please don't provide your personal details to such mail

Friday, August 23, 2013

Cyber Warfare a Global Digital Weapon

Not every battle starts from ground, air or water…These days, you'll find some of the fiercest fighting going on between computer networks. The Digital Age has transformed the way weapon are been used. Digital Weapon is the new terms referred across the organization & continents.  Rather than using bullets and bombs, the warriors in these confrontations use bits and bytes flowing over the public and protected network.

Cyberwar can be defined as Leveraging the Internet for political, military, and economic espionage activities. Cyber warfare is Politically motivated hacking to conduct sabotage and espionage.


Cyber warfare is a serious concern and only limited specialized skill resources are required, unlike traditional warfare where massive resources, weapon, and equipment are required. The cyber defense should be considered as the fourth arm after the army, navy and air force. Nations are spending huge investment in building young talent for establishing R&D center to defuse/activate attack. The objective is to steal sensitive information about the weapon, strategic and other information which may act as a major decision factor during the war. The reach of such attacks are more since all developed or developing countries are heavily depended on internet and attack can be initiated across the globe.

In today's scenario, many of the Government Sites are running with obsolete solution stack, Vulnerable deployment & coding practice, reactive threat management system making them prone for Cyber Attack.

Multiple cases that have been noticed for Cyber warfare between countries like US, South Korea, Pakistan, China, Israel &  India etc.

On  April 2013, Anonymous launched a cyber war against Israel. It was touted as  “the largest internet battle in history,” hitting 100,000 websites, 30,000 bank accounts, 40,000  Facebook pages and 5,000 Twitter accounts.

Indian Government Departments that have come under Repeated attacks Prime Minister's Office, Ministry of External Affairs, Indo-Tibetan Border Police and DRDO.According to official data, a total of 78 Indian government websites were hacked and 16,035 incidents related to spam, malware infection and system break-in were reported this year so far.

In India, their many agencies focused on Cyber defense are NTRO(National Technical Research Organization), National Critical Information Infrastructure Protection Center and CERT.